folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and v2018.08.09.00.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-18097 | folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and v2018.08.09.00. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 06 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2025-05-06T16:39:21.216Z
Reserved: 2018-01-26T00:00:00.000Z
Link: CVE-2018-6337
Updated: 2024-08-05T06:01:48.614Z
Status : Modified
Published: 2018-12-31T22:29:00.247
Modified: 2025-05-06T17:15:50.983
Link: CVE-2018-6337
No data.
OpenCVE Enrichment
No data.
EUVD